2025 CVE Vulnerabilities

45,255 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-8853CRITICAL9.8Official Document Management System developed by 2100 Technology has an Authentication Bypass vulnerability, allowing un...
CVE-2025-8839HIGH8.8A vulnerability was found in jshERP up to 3.5. This issue affects some unknown processing of the file /jshERP-boot/user/...
CVE-2025-8838CRITICAL9.8A vulnerability has been found in WinterChenS my-site up to 1f7525f15934d9d6a278de967f6ec9f1757738d8. This vulnerability...
CVE-2025-8837HIGH7.8A vulnerability was identified in JasPer up to 4.2.5. This affects the function jpc_dec_dump of the file src/libjasper/j...
CVE-2025-8836LOW3.3A vulnerability was determined in JasPer up to 4.2.5. Affected by this issue is the function jpc_floorlog2 of the file s...
CVE-2025-8747HIGH7.8A safe mode bypass vulnerability in the `Model.load_model` method in Keras versions 3.0.0 through 3.10.0 allows an attac...
CVE-2025-8661MEDIUM6.1A stored Cross-Site Scripting vulnerability (XSS) occurs when the server does not properly validate or encode the data e...
CVE-2025-8660CRITICAL9.8Privilege escalation occurs when a user gets access to more resources or functionality than they are normally allowed.
CVE-2025-8835MEDIUM5.5A vulnerability was found in JasPer up to 4.2.5. Affected by this vulnerability is the function jas_image_chclrspc of th...
CVE-2025-8834LOW2.4A vulnerability has been found in JCG Link-net LW-N915R 17s.20.001.908. Affected is an unknown function of the file /wir...
CVE-2025-8833HIGH8.8A vulnerability was identified in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801. This issue a...
CVE-2025-8832HIGH8.8A vulnerability was determined in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801. This vulnera...
CVE-2025-7965MEDIUM4.3The CBX Restaurant Booking WordPress plugin through 1.2.1 does not have CSRF check in place when updating its settings, ...
CVE-2025-8854CRITICAL9.8Stack-based buffer overflow in LoadOFF in bulletphysics bullet3 before 3.26 on all platforms allows remote attackers to ...
CVE-2025-8831HIGH8.8A vulnerability was found in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801. This affects the ...
CVE-2025-8830HIGH8.8A vulnerability has been found in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801. Affected by ...
CVE-2025-8829HIGH8.8A vulnerability was identified in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801. Affected by ...
CVE-2025-8828HIGH8.8A vulnerability was determined in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801. Affected is ...
CVE-2025-8827HIGH8.8A vulnerability was found in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801. This issue affect...
CVE-2025-27577HIGH7in OpenHarmony v5.0.3 and prior versions allow a local attacker arbitrary code execution in tcb through race condition.
CVE-2025-27562MEDIUM5.5in OpenHarmony v5.0.3 and prior versions allow a local attacker case DOS through missing release of memory.
CVE-2025-27536MEDIUM5.5in OpenHarmony v5.0.3 and prior versions allow a local attacker cause DOS through type confusion.
CVE-2025-27128HIGH7.8in OpenHarmony v5.0.3 and prior versions allow a local attacker arbitrary code execution in tcb through use after free.
CVE-2025-26690MEDIUM5.5in OpenHarmony v5.0.3 and prior versions allow a local attacker case DOS through NULL pointer dereference.
CVE-2025-25278HIGH7in OpenHarmony v5.0.3 and prior versions allow a local attacker arbitrary code execution in tcb through race condition.

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now